ransomware Credible South Africa (ZA) hospitality

Singita listed by the DragonForce ransomware group

Singita

📅 02 April 2026
CompanySingita
CountrySouth Africa (ZA)
Sectorhospitality
Breach date2026-04-02
People affectedNot disclosed
Ransomware groupdragonforce
Data typesguest data, reservation records, corporate information

Overview

The DragonForce ransomware group has listed Singita, a South African luxury safari and conservation hospitality company operating lodges and camps across Africa, on its leak site. The listing appeared on 2 April 2026.

What was published

The group claims to have exfiltrated data from the company. Luxury hospitality operations hold guest profiles, reservation records and corporate information, which are the likely contents of any exfiltration.

Risks for affected individuals

  • Guests' personal data may be exposed.
  • Reservation and payment records could enable fraud.
  • Employees' information may be included.

What remains unknown

  • The volume of records involved.
  • Whether the data has been published.
  • The response status of the company.

What affected people should do

Guests should monitor payment activity and be cautious of unsolicited messages referencing the company. Singita should notify affected guests and staff, review compromised systems, and communicate the scope of the incident.

Singita leak listing

Sources

  • http://z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onion/blog/?post_uuid=0e64a450-0c5f-43d6-911e-81456466f406